Excessive Logging problem in /var/log

Destin J Funk destinjfunk at gmail.com
Fri Oct 5 11:27:40 UTC 2018


Dear all Ubuntu Users and developers,

I have a problem. More than 4G in this directory 
*******@***:~$ sudo du --summarize -h /var/log
4.2G	/var/log

Then I deleted most of the logging files with sudo rm /var/log/* and restarted the computer. I rechecked the directory with 
*******@***:~$ sudo du --summarize -h /var/log/*
316K	/var/log/apt
24K	/var/log/asterisk
4.0K	/var/log/auth.log
8.0K	/var/log/boot.log
0	/var/log/btmp
44K	/var/log/cups
4.0K	/var/log/dist-upgrade
4.0K	/var/log/gdm3
4.0K	/var/log/gpu-manager.log
8.0K	/var/log/hp
7.9M	/var/log/installer
4.2G	/var/log/journal
92K	/var/log/kern.log
4.0K	/var/log/lastlog
4.0K	/var/log/openvpn
4.0K	/var/log/speech-dispatcher
276K	/var/log/syslog
28K	/var/log/unattended-upgrades
4.0K	/var/log/wtmp
40K	/var/log/Xorg.0.log

in /var/log/journal file, more than 4G of data in it. I run in command line 
*******@***:~$ journalctl and I saw a repetitive log from audit. I Press Pg Dn and all the log are the same. This is a snapshot of it

Jul 20 02:11:51 ******** kernel: audit: type=1400 audit(1532038310.949:1616565): apparmor="DENIED" operation="open" profile="snap.gnome-system-monitor.gnome-system-monitor" name="/proc/1/cgroup" pid=6664 comm="gnome-system-mo" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
Jul 20 02:11:49 ******** audit[6664]: AVC apparmor="DENIED" operation="open" profile="snap.gnome-system-monitor.gnome-system-monitor" name="/proc/503/cgroup" pid=6664 comm="gnome-system-mo" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0 
Jul 20 02:11:55 ******** kernel: kauditd_printk_skb: 7693 callbacks suppressed

I am running a desktop version Ubuntu 18.04 with latest update. I did not change any configuration for audit and the apparmour.
Can someone help me solve with this problem.

--------------------------------------------






More information about the ubuntu-users mailing list